PaperPlane

Privacy Notice

Last updated: 19 September 2026. This notice is written for an India-first marketplace and is intended to be updated as the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 become fully applicable on their notified timelines.

1. Who we are

PaperPlane is a marketplace project connecting creators, brands and independent creative professionals. Before public launch, the operator's legal name, registered address and official privacy/grievance contact must be inserted below.

2. Data we collect

We aim to collect only data reasonably needed for the service and stated purposes.

3. Purposes and legal basis

PaperPlane uses personal data to create and secure accounts, provide marketplace functionality, facilitate communications, prevent abuse, maintain records required by law, respond to support requests and improve reliability. Where consent is the basis for processing, it should be informed, specific and capable of withdrawal as provided by applicable law.

4. Public information

Profile information you choose to publish may be visible to other PaperPlane users. Do not publish private contact details, government identifiers, passwords, financial credentials or another person's personal information.

5. Children

PaperPlane currently restricts account registration to people aged 18 or older. We do not knowingly accept account registrations from children. The DPDP Act contains specific protections for children's personal data, including parental-consent requirements and restrictions on detrimental processing and tracking.

6. Your rights and requests

Subject to applicable law, you may request access to information about processing, correction/update, erasure where applicable, withdrawal of consent where consent is the legal basis, and grievance redressal. Contact TODO: INSERT OFFICIAL CONTACT EMAIL and include the account email and request type. We may need to verify identity before acting.

7. Security and breaches

PaperPlane uses Supabase Auth, database access controls, row-level security and server-side authorization. We will maintain reasonable technical and organisational safeguards and follow applicable breach-notification requirements. The 2025 DPDP Rules include security safeguards and breach-intimation requirements, with detailed provisions coming into force on the notified phased timeline.

8. Retention and deletion

We retain information only for as long as reasonably necessary for the stated purpose, user requests, security, dispute handling and legal obligations. Certain retention duties may apply under the DPDP Rules and other laws. We do not use the 3-year rule for large e-commerce entities as a blanket retention promise for a small platform; applicable thresholds and commencement dates matter.

9. Service providers and transfers

PaperPlane uses Supabase for authentication, database and storage infrastructure. Other service providers may be added only where needed. Cross-border processing or transfers will be handled subject to applicable Indian law and contractual/security requirements.

10. Contact

Privacy and data requests: TODO: INSERT OFFICIAL CONTACT EMAIL